在 Google gVisor 于 20260831.0 版本之前的所有平台中,虚拟文件系统(VFS)存在一个释放后使用(use-after-free)漏洞。具有标准容器权限的本地攻击者可以通过双重释放(double-free)来自沙箱内覆盖文件系统的底层 MemoryFile,从而在主机 sentry 进程中实现代码执行。sentry 进程仍受主机级 Linux seccomp 和命名空间边界的限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet